Senior Penetration Tester
Job Description
Carson and SAINT is hiring a Senior Penetration Tester for remote work focused on in-scope vulnerability discovery and actionable reporting.
Responsibilities
- Perform comprehensive penetration testing against internal and/or external environments across organizations, covering network, servers, workstations, applications, API, and online/cloud services.
- Assess and attempt to bypass existing information security controls.
- Conduct network and application vulnerability assessments.
- Produce penetration testing reports with technical details, risk analysis, and remediation recommendations for identified issues.
- Participate in project-related meetings, including information gathering, solution design, and project checkpoint discussions.
- Act as a subject matter expert for network security, application security, and attack and defense techniques, including countermeasures.
What You Will Do
- Use up-to-date automated and manual penetration testing tools and techniques to support discovery, enumeration, exploitation, and reporting.
- Work within permitted engagement activities, aligned to the rules of engagement.
- Assist in developing rules of engagement and reporting documentation.
- Partner with the client to provide remediation or mitigation strategies as required.
Team Mission
- Deliver comprehensive, in-depth identification of exploitable vulnerabilities within agreed engagement scope to protect customer data and reputation.
- Ensure testing does not negatively impact the confidentiality, availability, or integrity of client system data.
Requirements
- Minimum 7+ years of experience as a network and application penetration tester.
- Hold OSCP/OSCE, CREST, GPEN, CEH, or an equivalent certification.
- University Degree or College Diploma in Computer Sciences, Information Technology, or a related field, or an equivalent combination of education and experience.
Preferred Skills and Expertise
- Demonstrated hands-on experience (minimum 5-10 years) conducting external and internal penetration tests across operating systems, web applications, and networks.
- Experience running and managing network and application vulnerability scanning and assessment tools.
- Technical knowledge of current vulnerabilities, exploits, and tools (commercial and open source).
- Strong understanding of security industry best practices and procedures.
- Experience following security assessment frameworks and penetration testing methodologies, including both manual and automated testing.
- Ability to research evolving exploits, techniques, and tools to support penetration testing efforts.
- Experience developing security tools and using scripts/utilities to automate assessment and analysis activities.
- Experience maintaining a target-rich lab environment to support training and development/testing of advanced exploits.
- Experience sustaining an up-to-date penetration testing toolbox.
Certifications and Technical Alignment
- OSCP, OSCE (OSCE noted as beneficial under professional offensive security certifications)
- CREST, GPEN, CEH
- GIAC security certifications (GPEN, GWAPT, GXPN)
- Qualified/Licensed Penetration Tester (Q/LPT), Certified Penetration Tester (CPT)
- CompTIA Certified Ethical Hacker (CEH)
- CISSP, CISA, CISM, CRMP, CRISC, ISSMP
- OSWE, OSCE noted as beneficial
Soft Skills
- Excellent verbal and written communication skills, including clear and concise assessment reports with findings, recommendations, road maps, and actionable plans.
- Exceptional customer service, communication, and interpersonal skills.
- Ability to communicate and work with executives, peers, and employees at all levels.
- Ability and willingness to work outside business hours (weekends/evenings).
- Strong time management and organizational skills.
- High degree of integrity, competence, adaptability, resilience, and initiative.
- Maintain relevant industry certifications and willingness to work toward additional credentials.
Additional Desired Qualifications
- Experience testing mobile applications, social engineering, phishing, vishing, physical security, wireless networks, and more.
- Consulting experience leveraging offensive methodologies in red and blue team penetration testing.
- Experience curating technical and non-technical documentation referencing internal processes and procedures.
- Knowledge of security compliance policy, programs, processes, and metrics.
- Ongoing research into security trends, new testing techniques, and best practices, with knowledge sharing across the team.
Location
- Remote
Pay
- USD 125,000 - 145,000 per year
Benefits
- 401(k)
- Dental insurance
- Flexible spending account
- Health insurance
- Health savings account
- Life insurance
- Paid time off
- Professional development assistance
- Referral program
- Retirement plan
- Vision insurance